PHP Security Breach
data:image/s3,"s3://crabby-images/919e1/919e11a85e864c52d99d74139de0178e91364aec" alt=""
data:image/s3,"s3://crabby-images/2cbdb/2cbdbd6b7d742cc04e59bd15d66705e091370549" alt=""
data:image/s3,"s3://crabby-images/5da99/5da995782fc0cb9b7279bbeba676fa5d79aad115" alt=""
data:image/s3,"s3://crabby-images/4ea5d/4ea5dc2f6162f837a830c1a651eda323a7e714d3" alt=""
data:image/s3,"s3://crabby-images/122cf/122cf21ab817d8bc12619e8aa3c30e8c06e27a29" alt=""
data:image/s3,"s3://crabby-images/2b85f/2b85fa0a0b92feb0817f68eda6ff679871aa1e7d" alt=""
data:image/s3,"s3://crabby-images/a5725/a572522598411180918de128a1efc0156085534f" alt=""
Share:
Sponsors:
I urge all our users to make the following change to viewtopic.php as a matter of urgency. Open viewtopic.php in any text editor. Find the following section of code:
//
// Was a highlight request part of the URI?
//
$highlight_match = $highlight = '';
if (isset($HTTP_GET_VARS['highlight']))
{
// Split words and phrases
$words = explode(' ', trim(htmlspecialchars(urldecode($HTTP_GET_VARS['highlight']))));
for($i = 0; $i < sizeof($words); $i++)
{
and replace with:
//
// Was a highlight request part of the URI?
//
$highlight_match = $highlight = '';
if (isset($HTTP_GET_VARS['highlight']))
{
// Split words and phrases
$words = explode(' ', trim(htmlspecialchars($HTTP_GET_VARS['highlight'])));
for($i = 0; $i < sizeof($words); $i++)
{
Note: Please inform as many people as possible about this issue. If you're a hosting provider please inform your customers if possible. Else we advise you implement some level of additional security if you run ensim or have PHP running cgi under suexec, etc.
If your hosted by Codezhost... no worries we have suexec shutdown and nothing can be called from it.
Article submitted by: Telli
Last Update: 12-05-2004
Category: Security
//
// Was a highlight request part of the URI?
//
$highlight_match = $highlight = '';
if (isset($HTTP_GET_VARS['highlight']))
{
// Split words and phrases
$words = explode(' ', trim(htmlspecialchars(urldecode($HTTP_GET_VARS['highlight']))));
for($i = 0; $i < sizeof($words); $i++)
{
and replace with:
//
// Was a highlight request part of the URI?
//
$highlight_match = $highlight = '';
if (isset($HTTP_GET_VARS['highlight']))
{
// Split words and phrases
$words = explode(' ', trim(htmlspecialchars($HTTP_GET_VARS['highlight'])));
for($i = 0; $i < sizeof($words); $i++)
{
Note: Please inform as many people as possible about this issue. If you're a hosting provider please inform your customers if possible. Else we advise you implement some level of additional security if you run ensim or have PHP running cgi under suexec, etc.
If your hosted by Codezhost... no worries we have suexec shutdown and nothing can be called from it.
Article submitted by: Telli
Last Update: 12-05-2004
Category: Security
Current rating: 5.31 by 54 users
Would you recommend this article to a friend? |
Not a Chance | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | Absolutely |
Related News Stories
(9,527 reads) 07-05-2008
· Fusion Security(15,180 reads) 06-02-2007
· NukeSentinel(tm)2.5.10 Critical Update(13,950 reads) 05-07-2007
· NukeSentinel(tm) 2.5.08 Maintainance Release(15,408 reads) 03-15-2007
· NukeSentinel(tm) 2.5.07 Reissued: Critical Update(13,916 reads) 03-02-2007
· NukeSentinel(tm) 2.5.06: Critical Update(14,670 reads) 01-23-2007
· NukeSentinel(tm) 2.5.05 released(14,692 reads) 12-24-2006
· NukeSentinel 2.5.04 released(14,424 reads) 11-03-2006
· NukeSentinel(tm) 2.5.03 Released(18,265 reads) 10-19-2006
· Php Nuke 8.0 Patched(14,658 reads) 10-01-2006
· ipBan Modification
Please register or sign-in to post comments.